VendorsNASAcore_flight_systemall versions
Vulnerabilities

NASA Core Flight System (cFS)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2025-25373
The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform.
Published 2025-03-25 · Analyzed
9.8EPSS 0.005
CVE-2026-5474
NASA cFS CCSDS Packet Header to_lab_passthru_encode.c CFE_MSG_GetSize heap-based overflow
Published 2026-04-03 · Analyzed
8.8EPSS 0.006
CVE-2025-25371
NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the system.
Published 2025-03-25 · Analyzed
7.5EPSS 0.006
CVE-2025-25372
NASA cFS (Core Flight System) Aquila is vulnerable to segmentation fault via sending a malicious telecommand to the Memory Management Module.
Published 2025-03-25 · Analyzed
7.5EPSS 0.005
CVE-2025-25374
In NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the launch of any external application, causing a platform denial of service.
Published 2025-03-25 · Analyzed
7.5EPSS 0.005
CVE-2026-5473
NASA cFS Pickle pickle.load deserialization
Published 2026-04-03 · Analyzed
7.0EPSS 0.004
CVE-2026-5475
NASA cFS CCSDS Header Size cfe_sb_priv.c CFE_SB_TransmitMsg memory corruption
Published 2026-04-03 · Analyzed
5.5EPSS 0.003
CVE-2026-5476
NASA cFS cfe_tbl_passthru_codec.c CFE_TBL_ValidateCodecLoadSize integer overflow
Published 2026-04-03 · Analyzed
4.6EPSS 0.003